Server definition
- Hash
- sha256:3dfc12c2e296953ec61ec83f6f58a377ce21f6d2e25180af10de3841d864f595
- What it is
- What a remote MCP server returned when asked what it offers: 4 tools
The blob, as servednamed by its sha256
{
"instructions": "Tollbooth OAuth2 Collector — unauthenticated mailbox for OAuth2 authorization codes. This is a community utility with no monetization.\n\n## How It Works\n\n1. An MCP server directs the user's browser to an OAuth provider, with `redirect_uri` pointing to the serverless callback function.\n2. After the user authorizes, the provider redirects the browser to the callback, which calls `store_code` on this collector via MCP.\n3. The originating MCP server calls `retrieve_code(state=...)` to pick up the encrypted code (one-time read, auto-deleted).\n\n## Tools\n\n- `store_code` — Store an encrypted authorization code (called by the serverless callback).\n- `retrieve_code` — Retrieve and delete a stored code (called by the originating MCP server).\n- `collector_status` — Health check showing pending code count and TTL.\n- `service_status` — Report the running build (incl. the deployed git sha) so a redeploy can be verified.",
"tools": [
{
"description": "Health check — shows the number of pending authorization codes and TTL.",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "collector_status",
"outputSchema": {
"additionalProperties": true,
"type": "object"
}
},
{
"description": "Retrieve a stored authorization code (one-time read, auto-deleted).\n\nCalled by the originating MCP server to pick up the code after the user\nhas authorized in the browser. Returns the encrypted code which the\ncaller decrypts using the same state token.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"state": {
"description": "The state token (patron npub) used during authorization.",
"type": "string"
}
},
"required": [
"state"
],
"type": "object"
},
"name": "retrieve_code",
"outputSchema": {
"additionalProperties": true,
"type": "object"
}
},
{
"description": "Report the running build so a redeploy can be verified. Free.\n\nDelegates to the SDK's canonical ``build_service_status`` — the single\nsource of the service_status payload shape — so this collector reports the\nsame envelope as every other DPYC service. The load-bearing field is\n``build_info.fastmcp_cloud_git_commit_sha``: the commit Horizon actually\ndeployed. The post-merge deploy-verify probe reads it to confirm the live\nservice redeployed the merged sha; with no ``service_status`` tool to probe,\nthat sha reads as ``<none>`` and an otherwise-healthy deploy is flagged as\n\"did not land\".\n\nThe vault/courier/operator fields are ``False``/empty by construction —\nthis is an unauthenticated community utility with no operator runtime.",
"inputSchema": {
"additionalProperties": false,
"properties": {},
"type": "object"
},
"name": "service_status",
"outputSchema": {
"additionalProperties": true,
"type": "object"
}
},
{
"description": "Store a sealed OAuth2 authorization code.\n\nCalled by the serverless callback function after the browser redirect. The\n``state`` carries BOTH the patron npub (the lookup/retrieve key) and the\noperator npub (the PUBLIC key the code is sealed to) — see the SDK's\n``pack_oauth_state``. The code is sealed with NIP-44 to the operator so only\nthat operator's nsec can open it; the Neon row is keyed by the patron npub,\nso retrieval (``retrieve_code(state=patron_npub)``) is unchanged.",
"inputSchema": {
"additionalProperties": false,
"properties": {
"code": {
"description": "The authorization code from the OAuth provider.",
"type": "string"
},
"state": {
"description": "The packed state (``patron_npub.operator_npub``).",
"type": "string"
}
},
"required": [
"code",
"state"
],
"type": "object"
},
"name": "store_code",
"outputSchema": {
"additionalProperties": true,
"type": "object"
}
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:3dfc12c2e296953ec61ec83f6f58a377ce21f6d2e25180af10de3841d864f595 | sha256sum